---------------------------
Title: California Opt Me Out Act: What Website Owners Should Know
URL: https://www.cookiebot.com/us/california-opt-me-out-act/
---------------------------

# California Opt Me Out Act: What Website Owners Should Know

## At a Glance

- **Effective date:** January 1, 2027. CPRA-covered businesses must recognize opt-out preference signals, including Global Privacy Control (GPC), as legally valid "Do Not Sell or Share" requests.
- **Visual confirmation required:** Under CPPA regulations effective January 1, 2026, businesses must display a visible indicator confirming when a GPC signal has been recognized and acted upon.
- **No override prompts:** Displaying a consent banner that asks visitors to re-confirm or reverse a GPC signal is itself a regulatory violation.
- **Multi-state enforcement:** In September 2025, California, Colorado, and Connecticut launched a coordinated investigative sweep targeting GPC non-compliance — the first action of the Consortium of Privacy Regulators.
- **Scope:** Any for-profit business collecting personal data from California residents that meets the CPRA's coverage thresholds, regardless of where the business is physically based.
- **Compliance tool:** A consent management platform (CMP) that detects and responds to opt-out preference signals automatically is the most reliable way for website owners to meet these requirements.

The California Opt Me Out Act requires any CPRA-covered business to automatically honor browser-based opt-out signals as valid Do Not Sell or Share requests. This includes Global Privacy Control (GPC). This article covers the law's requirements, who it applies to, CPPA enforcement actions, and how to configure your consent management platform before the January 1, 2027 deadline.

The Opt Me Out Act expands on existing law, and represents a significant step in how California enforces consumer privacy rights online. Rather than relying solely on website controls, the law requires businesses to automatically detect and honor browser-based privacy signals.

For website owners running digital advertising, analytics, or any form of visitor tracking, this is a concrete, enforceable requirement with a hard deadline of January 1, 2027. This guide explains what the Opt Me Out Act requires, which organizations it covers, how California regulators are enforcing it, and the practical steps your website needs to take**.**

## **The California Opt Me Out Act: What Is It and How Does It Augment California Privacy Laws?**

The [California Opt-Out Preference Signal Act](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB566), referred to as the Opt Me Out Act, is a California statute that formalizes the obligation for businesses to honor automated privacy signals sent from consumers' browsers or devices.

It extends the framework of the [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/) and the [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/us/cpra/), which together established Californians' right to opt out of the sale or sharing of their personal information.

Where the CPRA allows consumers to exercise that right manually — through a ["Do Not Sell or Share My Personal Information"](https://usercentrics.com/us/guides/website-disclaimers/do-not-sell-my-personal-information/) link on a website — the Opt Me Out Act requires that the right can also be exercised automatically, through browser-based opt-out preference signals such as [Global Privacy Control (GPC)](https://www.cookiebot.com/us/global-privacy-control/).

The law is administered by the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/), publicly known as CalPrivacy, which is the independent agency established under the CPRA with authority to investigate, enforce, and issue binding privacy regulations in California.

### **How the Opt Me Out Act Fits Into California's Privacy Framework**

California has built its privacy regime in layers over several years. The CCPA, which came into force in 2020, gave consumers the right to opt out of the sale of their personal information. The CPRA, effective January 2023, extended that right to cover "sharing" for cross-context behavioral advertising.

CPPA obligations subsequently required that opt-out preference signals — including GPC — must be treated as valid opt-out requests. The Opt Me Out Act, taking effect January 1, 2027, codifies this requirement at the statutory level, meaning it cannot be undone by a future change in regulatory interpretation alone.

## **Global Privacy Control (GPC): What Is It and How Does It Work?**

GPC is a technical standard that allows consumers to communicate a "Do Not Sell or Share" preference automatically, at the browser or device level, without taking any action on individual websites. When a user enables GPC in a supported browser or privacy extension, the signal is sent to every website they visit with each page request. A consent banner or other opt-in/out mechanism doesn’t need to be displayed.

GPC was developed through a collaborative effort involving privacy researchers, technologists, and civil society groups. The CPPA has formally recognized it as a valid legal opt-out mechanism under the CPRA. As of 2026, browsers including Firefox, Brave, and DuckDuckGo support GPC natively.

### **How GPC Is Transmitted and Processed**

When a visitor with GPC enabled arrives on your site, the signal is included in the HTTP request header before the page finishes loading. A properly configured CMP reads this header and suppresses non-essential tracking scripts before they fire.

This has a specific technical implication: the processing must be blocked at the point of arrival, not after the page loads. The CMP cannot wait for a visitor interaction or present a consent prompt first. Additionally, a visual indicator must be displayed to confirm the signal has been received and honored, for example, by displaying a “GPC honored” notification on-page.

For website owners, this means the compliance requirement is architectural. The CMP must intercept the GPC signal before any tag manager, advertising pixel, or analytics script executes.

## **Which Businesses Does the Opt Me Out Act Apply To?**

The Opt Me Out Act applies to any for-profit business already covered by the CPRA. Coverage is determined by whether the business collects personal information from California residents and meets any one of the following thresholds:

- Annual gross revenues exceeding USD 25 million (adjusted periodically for the Consumer Price Index)
- Buying, selling, receiving for commercial purposes, or sharing the personal information of 100,000 or more consumers or households per year
- Deriving 50 percent or more of annual revenues from selling or sharing consumers' personal information

A business does not need to be based in California, or even in the U.S., to fall within scope. If it collects personal data from California residents and meets one of the thresholds above, it is covered.

### **Who Is Exempt and Why Exemptions Are Narrower Than They Appear**

Nonprofits, government agencies, and businesses that fall below all three CPRA thresholds are outside the scope of the Opt Me Out Act. However, the thresholds are not as easy to stay under as they may seem.

The 100,000-consumer threshold is based on the volume of personal data processed over the course of a year, separate from revenue. Many mid-sized e-commerce businesses, media publishers, and SaaS providers exceed this figure without recognizing it.

Any business that runs web analytics, operates a marketing CRM, or processes transaction data at scale should verify its position carefully.

## **Core Requirements Under the Opt Me Out Act**

The following obligations apply to all businesses subject to the Opt Me Out Act, which will be subject to enforcement by the CPPA and Attorney General’s office.

### **Recognize Opt-Out Signals Automatically**

When a visitor transmits a GPC signal or equivalent opt-out preference signal, the business must treat it as a valid "Do Not Sell or Share" request immediately. No further action by the consumer is required or permitted.

### **No Re-Confirmation or Override Prompts**

Businesses cannot display a consent banner or other prompt asking a consumer to confirm or reverse a GPC preference. If your current banner includes such a prompt, presenting it to a visitor who has already sent a GPC signal is a violation in itself.

### **Visual Confirmation of Signal Receipt**

Under CPPA requirements effective January 1, 2026, your website must display a visible indicator when a GPC signal has been recognized and processed. This adds a UI requirement on top of the underlying technical obligation.

### **Consistent Application Across All Tracking Categories**

The opt-out must apply across all processing that falls under "sharing" as the CPRA defines it. Suppressing advertising trackers while allowing analytics or data broker integrations to continue does not satisfy the requirement if those activities qualify as sharing.

### **No Financial Incentives to Override Opt-Out Preferences**

Businesses cannot offer discounts, rewards, or other financial benefits in exchange for a consumer agreeing to override their GPC signal or opt back into data sharing.

## U.S. state, federal, and global rules. Which ones apply to you?

Many businesses have obligations under multiple overlapping regulations. Find out exactly which ones apply to your business. No signup required, takes less than 2 minutes.

[Find My Regulations](https://www.cookiebot.com/en/regulations-finder/)

## **CPPA Enforcement: From Guidance to Active Investigation**

California regulators have moved well past the guidance phase on GPC. Enforcement activity is already underway, and the pattern of violations the CPPA targets is well documented.

### **The Sephora Settlement: Setting the Precedent**

In 2022, the California Attorney General reached a [USD 1.2 million settlement with Sephora](https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement) over violations that included failure to process GPC opt-out signals. This established a clear enforcement posture: GPC non-compliance is a substantive legal violation, not a minor technical oversight.

### **Multi-State Enforcement via the Consortium of Privacy Regulators**

In April 2025, privacy regulators from California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon formed the [Consortium of Privacy Regulators](https://cppa.ca.gov/announcements/2025/20250416.html) to coordinate enforcement across state privacy laws.

In September 2025, California, Colorado, and Connecticut [launched the Consortium's first coordinated investigative sweep](https://cppa.ca.gov/announcements/2025/20250909.html), targeting businesses that failed to honor GPC signals. This was not a hypothetical: businesses received investigative inquiries across multiple state jurisdictions simultaneously.

The implication for nationally operating businesses is direct: GPC compliance cannot be treated as a California-specific concern. If you are processing data from consumers in Colorado, Connecticut, or any of the other states requiring opt-out signal recognition, your obligations apply there too.

### **Common Patterns That Attract Enforcement Attention**

CPPA investigations have identified a consistent set of failure modes:

- Consent banners loading after tracking scripts have already fired
- CMPs that read the GPC header but do not suppress third-party tags before they execute
- Partial compliance, such as honoring GPC for advertising but not for analytics or data broker sharing
- Server-side tracking that continues for consumers who opted out via GPC client-side

Civil penalties under the CPRA reach USD 2,500 per unintentional violation and USD 7,500 per intentional violation (adjusted periodically for the Consumer Price Index). Because GPC signals are transmitted per visit, systemic non-compliance across a substantial visitor base can translate into material aggregate liability quickly.

## **Evolving GPC Requirements Across U.S. States**

California is the most prominent state requiring GPC recognition, but it is far from the only one. As of 2026, 12 U.S. states require businesses to honor opt-out preference signals, though the specific framing differs by jurisdiction. As of 2027, at least one additional state will require recognition of opt-out signals.

California, Colorado, and Connecticut explicitly require recognition of GPC by name. New Jersey references it as an example but does not mandate it exclusively. A further eight states — Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, Oregon, and Texas — require recognition of a universal opt-out mechanism (UOOM), with GPC qualifying in practice under each.

Businesses operating nationally therefore face a de facto standard on opt-out signal recognition across those 12 states, even without a federal privacy law. Implementing GPC recognition at the platform level via a CMP configured for automatic signal detection supports compliance across all applicable jurisdictions from a single deployment.

## **How to Prepare Your Website for Compliance**

Meeting the requirements of the Opt Me Out Act is a technical task as much as a legal one. Your [cookie consent](https://www.cookiebot.com/en/cookie-consent/) setup alone is not sufficient. If a visitor’s browser sends a GPC signal, your cookie banner shouldn’t even appear.

A banner that prompts visitors to override a GPC signal also actively compounds the violation. The steps below outline what website owners need to address before the January 1, 2027 effective date.

### **Audit Your Site's Current Signal Handling**

Determine whether your website currently reads GPC headers, and whether your CMP prevents tracking scripts from loading when the signal is present. This requires reviewing your tag manager configuration and the order in which scripts execute. This is a technical audit, not a policy review.

### **Configure Your CMP to Detect and Honor GPC Automatically**

A comprehensive [consent management platform](https://www.cookiebot.com/us/cookie-consent-solution/) detects the GPC signal on page arrival and treats it as a "Do Not Sell or Share" instruction, suppressing all downstream data processing without requiring any visitor interaction.

### **Add Visual Confirmation to Your Site**

Since January 2026, California businesses must display a visual indicator when a GPC signal is recognized. This is a UI obligation in addition to the underlying technical one, and needs to be implemented on any page where GPC signals may be received. This could be provided as a ribbon or pop-up displaying “GPC honored” or by other means.

### **Review Your Consent Banner for Illegal Override Prompts**

If your banner asks visitors to confirm or override their GPC setting, remove it. Presenting such a prompt to a visitor who has already sent a GPC signal is a violation regardless of intent.

### **Include Server-Side Tracking in Your Audit**

[Server-side implementations](https://usercentrics.com/server-side-tracking-solution/) and [Meta Conversions API](https://usercentrics.com/knowledge-hub/meta-signals-gateway-capi-limitations/) configurations are subject to the same opt-out signal requirements as client-side tracking. If GPC is honored for client-side tags but server-side data transmission continues for opted-out visitors, the opt-out has not been honored. Review your server-side tagging setup as part of your compliance audit.

### **Document Your Signal Handling for Audit Readiness**

In the event of a CPPA investigation, businesses must demonstrate that their systems reliably honored GPC signals. Logging signal receipt alongside your standard consent records creates an auditable record.

## **How Cookiebot by Usercentrics Supports Opt Me Out Act Compliance**

Managing GPC and opt-out preference signals manually is operationally complex: it requires staying current with every browser implementation, maintaining tag configurations, keeping visual confirmation elements up to date, and extending that management across multiple jurisdictions. [Cookiebot by Usercentrics](https://www.cookiebot.com/us/cookie-consent-solution/) automates this process as part of its cookie consent management platform, supporting compliance with California's Opt Me Out Act and equivalent requirements across all U.S. states.

### **Automatic GPC Detection and Blocking**

When a visitor with GPC enabled arrives on your website, Cookiebot CMP detects the signal automatically and suppresses all non-essential data processing before any tracking scripts execute. No manual configuration per visit and no visitor interaction is required to trigger the opt-out.

Where a visitor has previously interacted with the consent banner and a stored consent choice exists, that choice is respected in place of the GPC signal.

### **Visual Confirmation Built In**

Cookiebot includes configurable UI elements that display the appropriate visual indicator when a GPC opt-out has been processed, satisfying the CPPA's implementation requirement without requiring custom development from your team.

### **Consistent Signal Handling Across All Applicable Jurisdictions**

Because Cookiebot applies GPC and universal opt-out mechanism recognition at the platform level, a single deployment covers opt-out signal obligations across California, Colorado, Connecticut, and the broader group of states requiring UOOM compliance. You do not need separate configurations per state.

### **Consent Records for CPPA Audit Readiness**

Cookiebot logs consent and opt-out decisions, including GPC signal receipt, in a centralized record. If a CPPA investigation is initiated, this documentation supports your ability to demonstrate that signal handling operated correctly and consistently.

## Take action before enforcement does

CalPrivacy is actively investigating and penalizing businesses for non-compliant data collection and consent management. Start your free trial to see what’s running on your website.

[Start free](https://www.cookiebot.com/en/free-trial/)

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)